Swaplanguage logo

Swaplanguage

swaplanguage.com
Moderate Risk
Updated September 10, 2026

Swap Language is a Danish (EU-based) language-learning and language-exchange platform serving individuals and companies. Its policy documents are written in plain, non-legalistic prose and assert GDPR coverage, EU-only data storage in Amsterdam, and use of Stripe for payments. However, the documents are silent or vague on many core protections: there is no named security certification (SOC 2, ISO 27001), no explicit data-retention schedule beyond a 3-year anonymization rule and a 26-month Google Analytics window, extensive collection of profile/behavioral data used for marketing, and a Privacy Policy that reserves the right to change with 180-day delayed effectiveness and no direct notice. The service processes adult users (18+) but does collect a range of PII (location, IP, GPS, device data, chat content). For professional or business use, review is advised before submitting sensitive or proprietary data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The documents do not contain an explicit statement assigning ownership of user-submitted data (profile text, chat messages, references). The Terms address acceptable-use restrictions and Swap Language's own trademarks/content but are silent on who owns user-generated content, which is itself a gap.

Confidence
40%

Output Data Ownership

Moderate Risk

The service delivers lessons, quizzes and video material rather than AI-generated outputs, and the Terms grant users only a limited license to access that content. The documents do not address ownership of any output produced by or for the user, so this remains unclear.

Confidence
35%

Training Data Usage

Moderate Risk

The documents make no mention of AI or machine-learning model training, nor of using user inputs to train models. The product does not appear to be AI-first, but the silence means there is no explicit commitment either way; data is described as used for service improvement and marketing.

Confidence
45%

Data Retention & Deletion

Moderate Risk

Users can request full deletion by email and can deactivate/delete their profile in settings; chat messages are deleted upon profile deletion. Retention is otherwise governed by a 3-year inactivity anonymization rule and a 26-month Google Analytics window, but there is no comprehensive retention schedule or deletion SLA.

Confidence
70%

Third-Party Data Sharing

Moderate Risk

The Privacy Policy states data is not shared with outside companies except with user consent or for legal reasons, which is user-favorable. However, the platform's core matching function inherently exposes profile data to other users, and payment data is shared with Stripe; the documents also reference third-party sellers in the purchase flow without naming them, warranting moderate caution.

Confidence
60%

Opt-Out Rights

Low Risk

The policy provides several concrete opt-out and control mechanisms: marketing sharing is opt-in, users can withdraw consent by deactivating their profile, can control profile visibility, and can request deletion. Cookies can be refused via the browser. These are meaningful, if not exhaustive, controls.

Confidence
65%

Compliance & Certifications

Moderate Risk

The vendor asserts it is subject to and protected by the GDPR and operates under Danish law, with EU-only physical storage in Amsterdam. However, no third-party attestations or certifications (SOC 2, ISO 27001, ISO 42001) are named, and sector-specific frameworks (FERPA, COPPA) are not addressed — though as an adults-only edtech tool, FERPA/COPPA relevance is limited. GDPR is claimed rather than independently attested.

Confidence
60%

Model Explainability & Auditability

Moderate Risk

The documents do not describe any AI/ML model, nor any explainability, auditability, or enterprise audit capabilities. As the product does not appear to be model-driven, this is largely not applicable, but the silence means no transparency guarantees exist.

Confidence
40%

Security Practices & Breach History

Moderate Risk

The policy discloses SSL/TLS encryption in transit and limited internal access to data, and confirms payment card data is handled by Stripe and not stored in full. However, there is no mention of encryption at rest, penetration testing, bug bounty, incident response, breach notification procedures, or a dedicated trust/security center; a referenced safety-and-trust page was inaccessible.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The Terms distinguish Free Users, Subscribers, End consumers, and Companies (Pro plan), and describe differing billing, cancellation and scheduling rules by tier. However, the documents describe no difference in data handling, privacy protections, or security between free and paid/company tiers; the privacy commitments appear uniform.

Confidence
50%

Human Review of User Inputs

Moderate Risk

The vendor stores all chat messages and reserves the right to review content for moderation, harassment or unlawful behavior, and to delete profiles. It does not proactively review all content, but staff can access saved messages as evidence, so user communications are not private from the vendor.

Confidence
65%

Regulatory & Litigation Exposure

Moderate Risk

The documents address cooperation with authorities: Swap Language will disclose personal data to authorities under GDPR legal obligations and states it will contact police with information such as IP addresses in cases of fake information or harassment. No litigation history or disputes are disclosed.

Confidence
55%

PII & SPI Data Inventory

Moderate Risk

The service collects substantial PII — email, name, nationality, workplace/field, country of residence, profile pictures, IP/GPS/device location, device data, chat content, and payment method (via Stripe). Some fields (gender, nationality, education, occupation) approach sensitive categories and are explicitly used for marketing targeting, though most are disclosed with stated purpose. No highly sensitive SPI (health, biometrics, financial data beyond Stripe-handled cards) is collected.

Confidence
65%

Policy–Product Currency

Moderate Risk

The Terms carry a 'Last updated: 04.06.2026' date, well within 12 months of the 2026-09-10 analysis date, and the documents cover the product's core capabilities (courses, matching, chat, payments, company plans) visible in the product surface. However, the Privacy Policy has no discoverable effective date, and neither document mentions any AI/ML processing that a modern learning product might involve, so coverage of that dimension is unconfirmed; capping at YELLOW.

Confidence
55%

Cross-Document Consistency

Low Risk

Two documents were supplied (Privacy Policy and Terms of Service) and were compared. They are broadly consistent on GDPR coverage, Stripe payment handling, deletion via email, and Danish jurisdiction; no material or critical contradictions were identified between them.

Confidence
60%

You've read all 15 risk ratings for Swaplanguage. Create a free account to see the exact policy wording behind each rating.